|
|
 |
Virtual Patch for Hidden Text Exploit
By: Michael Shinn
on: Thu 24 of Apr, 2008 [22:00 UTC]
(629 reads)
Free Modsecurity 2.5 rules released
By: Michael Shinn
on: Tue 18 of Mar, 2008 [15:28 UTC]
(541 reads)
|
|
We've been providing 2.5 signatures and rules to our ASL customers for over a year, and are proud to announce the availability of these rules through the GotRoot? lab website. The free rules are delayed 30 days. Want the rules in real time? Well sign up now! Its only $79.95 a year for a real time subscription to the most comprehensive and widely used WAF rules on the Internet!
|
ASL 2.0 final beta out
By: Michael Shinn
on: Tue 05 of Feb, 2008 [00:18 UTC]
(998 reads)
We've been been working like mad men on ASL (especially Scott), and we're at the final Beta. 2.0 final is just around the corner. The GUI is slick, tons of new security features, vulnerability scanner, built in support portal and more. Check it out on the ASL website .
|
Site move complete
By: Michael Shinn
on: Mon 04 of Feb, 2008 [23:47 UTC]
(675 reads)
|
|
For anyone that had problems logging into their accounts, I do apologize for the delay fixing the site. The problem was very very very convulted. Ah the joys of moving boxes, upgrading PHP, MYSQL and Javascript. Logins should be working again for everyone.
|
Virtual Patching talk at SANS CDI
By: Michael Shinn
on: Wed 12 of Dec, 2007 [22:58 UTC]
(817 reads)
Virtual Patching article with SANS
By: Michael Shinn
on: Wed 12 of Dec, 2007 [22:48 UTC]
(875 reads)
Filter out iframe attacks
By: Michael Shinn
on: Sun 02 of Sep, 2007 [23:44 UTC]
(4103 reads)
iframe attacks seem to be taking a hold with many vulnerable websites. The problem obviously being vulnerable ap
plications, which we would all like to see fixed. However, not everyone can be so lucky as to have either perfect applications, or perfect countermeasures against these vulnerabilities. Enter output filtering. We've put together a special set of rules for anyone running apache. This will filter out all your iframe attacks.
|
Modsecurity 2.0 compatible rules released
By: Michael Shinn
on: Sun 22 of Oct, 2006 [19:45 UTC]
(2651 reads)
|
|
2.0 compatible rules were released today. Consider these beta quality rules until further testing is done. Also, the format of the rules has changed considerably in 2.0, so if you want production quality we recommend you use the 1.9 rules with modsecurity 1.9.4.
|
Incoming calls problems with Broadvoice and Asterisk
How to fix it
By: Michael Shinn
on: Thu 29 of Jun, 2006 [22:14 UTC]
(5213 reads)
Asterisk users of broadvoice may have noticed a problem with not recieving inbound calls today. It appears that something changed in the way Broadvoice sends their SIP packets, but we have the solution: Just make the following change to your extensions.conf file:
Look for the extensions.conf context for your incoming calls, in our case, its [from-broadvoice], and add this line at the end of your context:
exten => YOURPHONENUMBER,1,Goto(from-broadvoice,1,1)
Make sure you change the "from-broadvoice" to the name of your incoming calls context.
|
Flaw in Microsoft AntiSpyware Beta 1
By: Casey Priester
on: Wed 25 of Jan, 2006 [22:03 UTC]
( reads)
|
The current version of Microsoft AntiSpyware? Beta 1 (version 1.0.701) contains a bug which causes issues for multiple users of a Windows XP system.
Symptoms of the issue are:
1) When a user logs in, they recieve an "Unexpected Error; quitting" messagebox.
2) When uninstalling or installing MSAS, the user recieves an "Error 1904.Module C:\Program Files\Microsoft Antispyware\XXXXXXXX.dll failed to (un)register. HRESULT -2147220473" on multiple dlls, even when they are an Administrator.
The issue arises from improper registry key permissions.
We have come up with a non-optimal workaround for the issue (click Read More...), and we are currently working on a more advanced solution.
We have not tested MSAS for the issue on other systems at this time.
|
New signatures for Google Hacks and Search engine recons, probes and attacks
By: Michael Shinn
on: Sat 03 of Dec, 2005 [02:26 UTC]
( reads)
|
|
I've added a new ruleset to the collection, "recons.conf" that contains the start of a ruleset to detect and block attacks that originate from, so called, "Google Hacks" - or the art of detecting vulnerable software by simply searching for it with Google. These rules only work with modsecurity 1.9.x and up, as I'm also starting the process of adding ids, revs, severity and msg variables to the rules, so if you are using modsecurity 1.8.x, these rules will not work for you - and may not even load.
|
New change to main page
By: Michael Shinn
on: Sun 09 of Oct, 2005 [22:26 UTC]
( reads)
I've made some changes to the main entry page to the website. If you go directly to the main URL: http://www.gotroot.com , you should get the new entry page. Many sites have the articles page linked to as the starting page, and that will always work, so if you came into the site that way don't worry about it, but do try the new entry page and let me know what you all think about it.
|
|